First published: Tue Apr 28 2020(Updated: )
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tinyfilemanager | =2.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12103 is classified as a medium severity vulnerability due to its potential for misuse by authenticated users.
To fix CVE-2020-12103, update Tiny File Manager to a newer version that addresses the file backup copy functionality vulnerability.
CVE-2020-12103 affects users of Tiny File Manager version 2.4.1 who have authenticated access to the file management system.
The implications of CVE-2020-12103 include the risk of unauthorized file backup creation, potentially leading to data leakage.
As of now, there have been no specific reports indicating active exploitation of CVE-2020-12103 in the wild.